Update Info

openSUSE-2025-237


Security update for mosquitto


Type: security
Severity: moderate
Issued: 2025-07-05
Description:
This update for mosquitto fixes the following issues:

mosquitto was update to version 2.0.21:

* Broker

  * Fix clients sending a RESERVED packet not being quickly
    disconnected.
  * Fix bind_interface producing an error when used with an
    interface that has an IPv6 link-local address and no other
    IPv6 addresses.
  * Fix mismatched wrapped/unwrapped memory alloc/free in
    properties.
  * Fix allow_anonymous false not being applied in local only mode.
  * Add retain_expiry_interval option to fix expired retained
    message not being removed from memory if they are not
    subscribed to.
  * Produce an error if invalid combinations of
    cafile/capath/certfile/keyfile are used.
  * Backport keepalive checking from develop to fix problems in
    current implementation.

* Client library

  * Fix potential deadlock in mosquitto_sub if -W is used.

* Apps

  * mosquitto_ctrl dynsec now also allows -i to specify a clientid
    as well as -c. This matches the documentation which states -i.

- systemd service: Wait till the network got setup to avoid
  startup failure.
- Update to version 2.0.19 (CVE-2024-3935 boo#1232635, CVE-2024-10525 boo#1232636):



              

Packages


  • mosquitto-2.0.21-bp157.2.3.1